CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,216 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 20 of 105
- CVE-2022-40958MEDIUMCVSS 6.5EG 6.52022-12-22
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerab…
- CVE-2022-4145MEDIUMCVSS 4.3EG 4.32023-10-05
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
- CVE-2022-4170CRITICALCVSS 9.8EG 9.82022-12-09
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
- CVE-2022-41716HIGHCVSS 7.5EG 7.52022-11-02
Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A ma…
- CVE-2022-41878HIGHCVSS 7.2EG 7.22022-11-10
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected …
- CVE-2022-4188MEDIUMCVSS 4.3EG 4.32022-11-30
Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2022-41934CRITICALCVSS 9.9EG 9.92022-11-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity c…
- CVE-2022-42268HIGHCVSS 7.8EG 7.82023-01-13
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to cu…
- CVE-2022-42468CRITICALCVSS 9.8EG 9.82022-10-26
Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java pro…
- CVE-2022-42471MEDIUMCVSS 5.4EG 5.42023-01-03
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.4.0 through 6.4.2, FortiWeb version 6.3.6 through 6.3.20 may allow…
- CVE-2022-42472MEDIUMCVSS 4.2EG 5.42023-02-16
A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2…
- CVE-2022-42544HIGHCVSS 7.8EG 7.82022-12-16
In getView of AddAppNetworksFragment.java, there is a possible way to mislead the user about network add requests due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges ne…
- CVE-2022-4257CRITICALCVSS 6.3EG 9.82022-12-01
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument ho…
- CVE-2022-42797HIGHCVSS 7.8EG 7.82023-02-27
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.
- CVE-2022-4282HIGHCVSS 4.7EG 7.22022-12-05
A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The…
- CVE-2022-4300HIGHCVSS 6.3EG 8.82022-12-06
A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated …
- CVE-2022-4322HIGHCVSS 6.3EG 7.22022-12-07
A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecute of the file AbstractScheduleJob.java of the component Scheduled Task Handler. The manipulation leads to injection. I…
- CVE-2022-43562MEDIUMCVSS 3.0EG 5.42022-11-04
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-…
- CVE-2022-4364CRITICALCVSS 7.3EG 9.82022-12-08
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command…
- CVE-2022-43720MEDIUMCVSS 5.4EG 5.42023-01-16
An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue …
- CVE-2022-43756MEDIUMCVSS 5.9EG 5.92023-02-07
A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of service by supplying specially crafted git credentials. This issu…
- CVE-2022-43769CRITICALCVSS 8.8EG 9.0⚠ KEV2023-04-03
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
- CVE-2022-43883HIGHCVSS 6.5EG 7.52022-12-19
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local f…
- CVE-2022-43932HIGHCVSS 7.5EG 7.52023-01-05
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitra…
- CVE-2022-45048HIGHCVSS 8.4EG 8.42023-05-05
Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0.
- CVE-2022-45550CRITICALCVSS 9.8EG 9.82022-12-07
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
- CVE-2022-45801MEDIUMCVSS 5.4EG 5.42023-05-01
Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web based applications that construct LDAP statements based on user input. When an application fails to properly sanitize use…
- CVE-2022-45910MEDIUMCVSS 5.3EG 5.32022-12-07
Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory and Sharepoint ActiveDirectory authority connectors of Apache ManifoldCF allows an attacker to manipulate the LDAP search…
- CVE-2022-46162HIGHCVSS 8.8EG 8.82022-11-30
discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discours…
- CVE-2022-46169CRITICALCVSS 9.8EG 9.8⚠ KEV2022-12-05
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbit…
- CVE-2022-46180MEDIUMCVSS 5.0EG 5.02023-01-04
Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able …
- CVE-2022-46265MEDIUMCVSS 5.4EG 6.12022-12-13
A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability that could allow an attacker to spoof a Host header information and redirect users to mal…
- CVE-2022-46337CRITICALCVSS 9.8EG 9.82023-11-20
A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, thi…
- CVE-2022-46873HIGHCVSS 8.8EG 8.82022-12-22
Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This wou…
- CVE-2022-47028MEDIUMCVSS 5.5EG 5.52023-05-30
An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert.
- CVE-2022-47052MEDIUMCVSS 6.1EG 6.12023-01-26
The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerab…
- CVE-2022-47083HIGHCVSS 8.8EG 8.82023-01-10
A PHP Object Injection vulnerability in the unserialize() function Spitfire CMS v1.0.475 allows authenticated attackers to execute arbitrary code via sending crafted requests to the web application.
- CVE-2022-47583CRITICALCVSS 9.8EG 9.82023-10-19
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
- CVE-2022-4768CRITICALCVSS 6.3EG 9.82022-12-27
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_…
- CVE-2022-4864MEDIUMCVSS 5.4EG 5.42022-12-30
Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- CVE-2023-0040HIGHCVSS 7.5EG 7.52023-01-18
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to …
- CVE-2023-0302HIGHCVSS 7.8EG 7.82023-01-15
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository radareorg/radare2 prior to 5.8.2.
- CVE-2023-0476MEDIUMCVSS 6.5EG 6.52023-01-26
A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through bli…
- CVE-2023-0493MEDIUMCVSS 5.3EG 5.32023-01-26
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
- CVE-2023-1059HIGHCVSS 6.3EG 8.82023-02-27
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument …
- CVE-2023-1061HIGHCVSS 6.3EG 8.82023-02-27
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail …
- CVE-2023-1287CRITICALCVSS 9.0EG 9.82023-03-09
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
- CVE-2023-1523CRITICALCVSS 10.0EG 10.02023-09-01
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphica…
- CVE-2023-20057MEDIUMEG 5.32023-01-20
A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerabi…
- CVE-2023-20858HIGHCVSS 7.2EG 7.22023-02-22
VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use …
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →